Atomic Edge Product

AI-Powered CVE Analysis for WordPress Plugins

We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.

WordPress Proof of Concepts

AI-assisted vulnerability analysis with PoC demonstration

June 10, 2026

CVE-2026-10795: UpdraftPlus: WP Backup & Migration Plugin <= 1.26.4 Unauthenticated Authentication Bypass via UpdraftCentral udrpc PoC, Patch Analysis & Rule

High CVE-2026-10795 in Updraftplus (CVSS 8.1): UpdraftPlus: WP Backup & Migration Plugin. Atomic Edge summarizes impact, exploitability, and patch details. Update to 1.26.5.
June 10, 2026

CVE-2026-2827: Open User Map PRO <= 1.4.31 Unauthenticated Stored Cross-Site Scripting via 'oum_location_notification' PoC, Patch Analysis & Rule

Medium CVE-2026-2827 in Open User Map Pro (CVSS 4.7): Open User Map PRO. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
June 10, 2026

CVE-2026-8940: WP Meta Sort Posts <= 0.9 Cross-Site Request Forgery to Plugin Settings Update PoC, Patch Analysis & Rule

Medium CVE-2026-8940 in Wp Meta Sort Posts (CVSS 4.3): WP Meta Sort Posts. Atomic Edge summarizes impact, exploitability, and patch details.
June 10, 2026

CVE-2026-9185: 6Storage Rentals <= 2.22.0 Unauthenticated Insecure Direct Object Reference to Arbitrary User Disclosure and Modification via 'userId' Parameter PoC, Patch Analysis & Rule

High CVE-2026-9185 in 6storage Rentals (CVSS 7.5): 6Storage Rentals. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
June 10, 2026

CVE-2026-8904: FastPicker, an order picker and order management system (oms) for WooCommerce on steroids <= 1.0.2 Cross-Site Request Forgery via Settings Save PoC, Patch Analysis & Rule

Medium CVE-2026-8904 in Fastpicker (CVSS 4.3): FastPicker, an order picker and order management system (oms) for WooCommerce on steroids. Atomic Edge summarizes impact, exploitability, and patch details.
June 10, 2026

CVE-2026-8907: WP-Ultimate-Map <= 1.1 Cross-Site Request Forgery to Stored Cross-Site Scripting via 'zoom-level' Parameter PoC, Patch Analysis & Rule

Medium CVE-2026-8907 in Wp Ultimate Map (CVSS 6.1): WP-Ultimate-Map. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
June 10, 2026

CVE-2026-8910: WP Emoticon Rating <= 1.0.1 Cross-Site Request Forgery to Reflected Cross-Site Scripting via 'emo_settings' Parameter PoC, Patch Analysis & Rule

Medium CVE-2026-8910 in Wp Emoticon Rating (CVSS 6.1): WP Emoticon Rating. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
June 10, 2026

CVE-2026-8909: WpMobi <= 0.0.3 Cross-Site Request Forgery via save_general_settings Action PoC, Patch Analysis & Rule

Medium CVE-2026-8909 in Wp Mobi (CVSS 4.3): WpMobi. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
June 10, 2026

CVE-2026-8902: AJAX Report Comments <= 2.0.4 Cross-Site Request Forgery to Settings Update PoC, Patch Analysis & Rule

Medium CVE-2026-8902 in Report Comments (CVSS 4.3): AJAX Report Comments. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
June 10, 2026

CVE-2026-8499: Helpfulcrowd Product Reviews <= 1.2.9 Inccorect Authorization via Type Juggling in 'token' Parameter to Arbitrary Settings Update PoC, Patch Analysis & Rule

Medium CVE-2026-8499 in Helpfulcrowd Product Reviews (CVSS 5.3): Helpfulcrowd Product Reviews. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
June 10, 2026

CVE-2026-8977: WP GDPR Cookie Consent <= 1.0.0 Authenticated (Subscriber+) Stored Cross-Site Scripting via 'ninja_gdpr_ajax_actions' AJAX Action PoC, Patch Analysis & Rule

Medium CVE-2026-8977 in Wp Gdpr Cookie Consent (CVSS 6.4): WP GDPR Cookie Consent. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
June 10, 2026

CVE-2026-8841: Extra Settings for RocketChat <= 0.1 Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes PoC, Patch Analysis & Rule

Medium CVE-2026-8841 in Extra Settings For Rocketchat (CVSS 6.4): Extra Settings for RocketChat. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
June 10, 2026

CVE-2026-7662: ePaperFlip Publisher <= 1 Authenticated (Contributor+) Stored Cross-Site Scripting via 'publicationid' Shortcode Attribute PoC, Patch Analysis & Rule

Medium CVE-2026-7662 in Epaperflip Publisher (CVSS 6.4): ePaperFlip Publisher. Atomic Edge summarizes impact, exploitability, and patch details.
June 10, 2026

CVE-2026-10862: Accordions <= 2.3.23 Authenticated (Custom+) Stored Cross-Site Scripting via Accordion Body Field PoC, Patch Analysis & Rule

Medium CVE-2026-10862 in Accordions (CVSS 6.4): Accordions. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
June 10, 2026

CVE-2026-5714: Enable Media Replace <= 4.1.8 Authenticated (Author+) Stored Cross-Site Scripting via 'location_dir' Parameter PoC, Patch Analysis & Rule

Medium CVE-2026-5714 in Enable Media Replace (CVSS 6.4): Enable Media Replace. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 4.1.9.
June 10, 2026

CVE-2026-9851: Booking Package <= 1.7.16 Authenticated (Editor+) Privilege Escalation via Account Takeover to updateUser AJAX Action PoC, Patch Analysis & Rule

High CVE-2026-9851 in Booking Package (CVSS 7.2): Booking Package. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.7.17.
June 10, 2026

CVE-2026-3011: Recipe Card Blocks Lite <= 3.4.13 Authenticated (Author+) Stored Cross-Site Scripting via 'summary' and 'notes' PoC, Patch Analysis & Rule

Medium CVE-2026-3011 in Recipe Card Blocks By Wpzoom (CVSS 6.4): Recipe Card Blocks Lite. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 3.4.14.
June 10, 2026

CVE-2026-7556: FV Flowplayer Video Player <= 7.5.49.7212 Unauthenticated Stored Cross-Site Scripting via Comment Text PoC, Patch Analysis & Rule

High CVE-2026-7556 in Fv Wordpress Flowplayer (CVSS 7.2): FV Flowplayer Video Player. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
June 10, 2026

CVE-2026-9829: Photo Gallery by 10Web <= 1.8.41 Authenticated (Contributor+) SQL Injection via 'compact_album_order_by' Shortcode Parameter PoC, Patch Analysis & Rule

Medium CVE-2026-9829 in Photo Gallery (CVSS 6.5): Photo Gallery by 10Web. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.8.42.
June 10, 2026

CVE-2026-9594: WP Maps <= 4.9.4 Authenticated (Admin+) Stored Cross-Site Scripting via 'location_messages' Parameter PoC, Patch Analysis & Rule

Medium CVE-2026-9594 in Wp Google Map Plugin (CVSS 4.4): WP Maps. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
Atomic Edge WAF security layer inspecting website traffic.

How Atomic Edge Works

Simple Setup. Powerful Security.

Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.

See How It Works